← Back home
Privacy
Privacy Policy
Last updated: May 2026
1. Introduction
StreamWorthy ("we", "us", "our") operates the StreamWorthy mobile application and website at streamworthy.app. This policy explains what data we collect, how we use it, and your rights.
2. Information we collect
- Account information: email address, username, display name, optional avatar image, optional bio, region
- User content: your watchlist and episode progress, ratings and reviews, custom lists, pinned shows, follows, blocks
- Subscription info: entitlement status (active / inactive) from RevenueCat. We don't receive card numbers.
- Notifications: your push-notification device token and your per-category preferences
- Analytics: product-usage events (e.g., "marked an episode watched") via PostHog, associated with your user ID
- Diagnostics: crash reports and performance traces, without sensitive personal data
3. Information we do NOT collect
- Precise location or GPS data
- Phone contacts or address book
- IDFA (iOS Advertising ID) or Google Advertising ID
- Browsing history outside StreamWorthy
- Screen recording, keystroke analytics, or microphone input
- Camera / photo library access (except one-time avatar uploads via the system photo picker)
- We do not use Facebook SDK, Google Analytics, or any advertising SDKs
4. How we use your information
- Provide the StreamWorthy service (sync your watchlist, progress, and follows across devices)
- Send push notifications you opted into (new episodes, friend activity, follow requests)
- Measure product usage so we know which features to improve — never for advertising
- We don't sell your personal data. Not to data brokers, not to advertisers, not to anyone.
5. Third-party services we use
- Supabase — database, authentication, and file storage
- Cloudflare — CDN and DDoS protection
- Resend — transactional email (magic-link sign-in, password reset)
- PostHog — product analytics, user-identified but never used for ads
- RevenueCat — subscription management. Processes purchase receipts, not PII beyond that.
- Expo Push / APNs / FCM — push notification delivery
- TMDB, OMDb — show metadata and ratings. We send zero user data to them; they never know who you are.
6. Data retention
- Account data: retained until you delete your account
- Analytics events: 12-month rolling retention, then automatically purged
- Crash logs: 90 days
7. Your rights
- Access — request a copy of your data
- Export — download your watchlist, ratings, and lists as JSON or CSV directly in the app
- Deletion — permanently delete your account and all associated data (Profile → Settings → Delete Account)
- Correction — edit your profile information at any time
- Email [email protected] for anything else
8. GDPR (for users in the EU/UK)
- Lawful basis: consent and legitimate interest
- Data Processing Agreement (DPA) in place with Supabase
- You may withdraw consent at any time by deleting your account
- You have the right to lodge a complaint with your local data-protection authority
9. CCPA (for California residents)
- We do not sell personal information — "Do Not Sell My Personal Information" does not apply
- You have the right to know, delete, and opt out — all are supported via in-app controls
10. Apple App Tracking Transparency
- StreamWorthy does not engage in cross-app tracking
- We do not use the IDFA
- The ATT prompt isn't required and we don't show it
11. Children's privacy
StreamWorthy is not directed at children under 13. We do not knowingly collect data from children under 13. If you believe we have, email [email protected] and we will delete it.
12. Changes to this policy
We may update this policy. We'll notify users of material changes via the app or email before they take effect.
13. Contact
- Email: [email protected]
- Website: streamworthy.app